Vulnerabilities exploitable today
372,980in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,214
- High8,146
- Medium6,165
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-10503—24.3%
——7——CVE-2025-24124—24.3%
——7——CVE-2025-46722—24.3%
——7——CVE-2026-402918.8 HIG24.3%
——7Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in the PUT /api/users/{id} endpoint allows any authenticated user with ROLE_STUDENT to escalate their privileges to ROLE_ADMIN by modifying the roles field on their own user record. The API Platform security expression is_granted('EDIT', object) only verifies record ownership, and the roles field is included in the writable serialization group, enabling any user to set arbitrary roles such as ROLE_ADMIN. Successful exploitation grants full administrative control of the platform, including access to all courses, user data, grades, and administrative settings. This issue has been fixed in version 2.0.0-RC.3.50dCVE-2022-28385—24.3%
——7——CVE-2025-2806—24.3%
——7——CVE-2023-1514—24.3%
——7——CVE-2026-768276.8 MED24.3%
——7A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.7dCVE-2026-326625.3 MED24.3%
——7Development and test API endpoints are present that mirror production functionality.50dCVE-2023-47453—24.3%
——7——CVE-2022-47654—24.3%
——7——CVE-2024-35764—24.3%
——7——CVE-2026-9092—24.3%
——7——CVE-2024-24841—24.3%
——7——CVE-2022-29211—24.3%
——7——CVE-2024-51518—24.3%
——7——CVE-2023-35041—24.3%
——7——CVE-2025-61775—24.3%
——7——CVE-2023-7306—24.3%
——7——CVE-2018-17486—24.3%
——7——CVE-2023-4893—24.3%
——7——CVE-2026-90778.5 HIG24.3%
——7IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.37dCVE-2023-1257—24.3%
——7——CVE-2014-1321—24.3%
——7——CVE-2025-15508—24.3%
——7——CVE-2024-6504—24.3%
——7——CVE-2024-32745—24.3%
——7——CVE-2024-3277—24.3%
——7——CVE-2021-28685—24.3%
——7——CVE-2024-36063—24.3%
——7——CVE-2026-331158.4 HIG24.3%
——7Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.50dCVE-2026-343956.5 MED24.3%
——7WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpoint returns all platform users with their personal information and wallet balances to any authenticated user. The endpoint checks User::isLogged() but does not check User::isAdmin(), so any registered user can dump the full user database. At time of publication, there are no publicly available patches.50dCVE-2025-0952—24.3%
——7——CVE-2025-68515—24.3%
——7——CVE-2026-664764.9 MED24.2%
——7Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.47dCVE-2026-876509.6 CRI24.2%
——7Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)3dCVE-2023-7245—24.2%
——7——CVE-2023-21988—24.2%
——7——CVE-2026-32888—24.2%
——7——CVE-2024-1137—24.2%
——7——